Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Travel Alberta

travelalberta.com

Group: Medusa

Discovered by ransomware.live: 2024-09-30

Estimated attack date: 2024-09-30

Country: CA

Description:

Travel Alberta ( founded in 2009 ),is a tourism marketing organization for the province of Alberta. Travel Alberta corporate office is located in 400-1601 9 Ave SE, Calgary, Alberta, T2G 0H4, Canada and has 110 employees. The total amount of data leakage is 799.80 GB

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 3

Third Party Employee Credentials: 0


External Attack Surface: 3



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • travelalberta-com.mail.protection.outlook.com.
TXT Records
  • globalsign-domain-verification=115756AFAB64434AC8CF8E0AC73C792D
  • onetrust-domain-verification=611ec712f9154f63a8559bb31dac86be
  • wgwnv.x.incapdns.net
  • MS=ms31808056
  • dJp2FJEpQxaSx7yUCSSaOInHJVUfkBW5cVGfmgbWF2mqhrqcXtcGZP3SSz3Wh+Hu1yaws+93Gsvv5OzU4uZGog==
  • google-site-verification=1qKIndTjKZ2Cf1qRfO3dPAMAVhXx98bFDhuTiMYLWII
  • miro-verification=4864dc381544e71cf74020d43dcf8d7712513b8c
  • globalsign-domain-verification=23C01308300330119083F55C955F35B0
  • jd3ubcv.impervadns.net
  • cwat2Va4pW23CX9F
  • v=spf1 include:mktomail.com include:sendgrid.net include:service-now.com include:spf.protection.outlook.com ip4:104.41.149.140 ip4:139.142.123.248/29 ip4:142.179.103.55/32 ip4:148.105.0.0/16 ip4:168.245.11.193 ip4:184.69.102.12/32 ip4:198.2.128.0/18 ip4:2" "05.201.128.0/20 ip4:208.98.199.170/32 ip4:208.98.199.171/32 ip4:208.98.199.172/32 ip4:208.98.199.173/32 ip4:209.139.250.65/28 ip4:40.121.144.77 ip4:52.233.62.247 ip4:64.251.76.244/28 ip4:72.2.4.128/32 ip4:97.111.17.218/32 -all
  • globalsign-domain-verification=9A71975CC0EE75B115785FF03AB1F6FA
  • facebook-domain-verification=924pa9r2gom7ezvc56i8ra4zqnfx8g
  • globalsign-domain-verification=67E43F650EE6ED84D4EB176F2C085007
  • globalsign-domain-verification=4FABF4D8FB0332A2F2B53B97364D3EF5
  • XojtlPXRiqoPGvmgEi+QkTGAry/7wT/xjGoIEUFBJCizeHXWt27FA61ujZp8LFVDesyWvoZwGK8uAJui8PSXtw==
  • google-gws-recovery-domain-verification= 39979175
Cloud / SaaS Services Detected
Microsoft 365 Marketo Miro SendGrid OneTrust

Leak Screenshot:

Leak Screenshot